[CFP] Call for Papers for Hardwear.io Security Conference Netherlands 2021 is OPEN
https://ift.tt/3rD3Ql4
Submitted August 20, 2021 at 07:41PM by hardweario
via reddit https://ift.tt/384oVf6
https://ift.tt/3rD3Ql4
Submitted August 20, 2021 at 07:41PM by hardweario
via reddit https://ift.tt/384oVf6
www.hardwear.io
Call for Papers | hardwear.io | Netherlands 2021
hardwear.io Netherlands 2021 - Hardware Security Conference & Training is seeking innovative research on attacks or mitigation on any hardware. Submit your research paper.
Lobste.rs Password Reset Vulnerability (via Timing Side-Channel)
https://ift.tt/2W47V6I
Submitted August 20, 2021 at 08:45PM by Soatok
via reddit https://ift.tt/37XNYAL
https://ift.tt/2W47V6I
Submitted August 20, 2021 at 08:45PM by Soatok
via reddit https://ift.tt/37XNYAL
Dhole Moments
Timing Attack on SQL Queries Through Lobste.rs Password Reset
Just to assuage any panic, let me state this up front. If you’re reading this blog post wondering if your Lobste.rs account is at risk, good news: I didn’t publish it until after the vu…
Cloudflare says it mitigated a record-breaking 17.2M rps DDoS attack
https://ift.tt/3iYGCDm
Submitted August 20, 2021 at 10:08PM by Snardley
via reddit https://ift.tt/3B00Kek
https://ift.tt/3iYGCDm
Submitted August 20, 2021 at 10:08PM by Snardley
via reddit https://ift.tt/3B00Kek
The Record by Recorded Future
Cloudflare says it mitigated a record-breaking 17.2M rps DDoS attack
Internet infrastructure company Cloudflare disclosed today that it mitigated the largest volumetric distributed denial of service (DDoS) attack that was recorded to date.
Facebook tool protects Afghan people who fear becoming Taliban targets
https://ift.tt/3k5PBBY
Submitted August 20, 2021 at 10:41PM by No_Fisherman_661
via reddit https://ift.tt/3z4gHQ8
https://ift.tt/3k5PBBY
Submitted August 20, 2021 at 10:41PM by No_Fisherman_661
via reddit https://ift.tt/3z4gHQ8
TechnoidHost
Facebook tool protects Afghan people who fear becoming Taliban targets | TechnoidHost
The Latest Facebook tool protects Afghan people who fear becoming Taliban targets. The Facebook toll launched by Facebook will help the people in fear of
Office 365 audit logging and its bypasses
https://ift.tt/3z4ZmXf
Submitted August 21, 2021 at 12:41AM by rikvduijn
via reddit https://ift.tt/3DeVVQu
https://ift.tt/3z4ZmXf
Submitted August 21, 2021 at 12:41AM by rikvduijn
via reddit https://ift.tt/3DeVVQu
Zolder - Applied Security Research
Office 365 audit logging | Zolder - Applied Security Research
It’s important to enable audit logging for o365 even if you are not monitoring them actively. Atleast if you get...
Understanding Network Access in Windows AppContainers
https://ift.tt/3sElmpK
Submitted August 21, 2021 at 11:41AM by 0xdea
via reddit https://ift.tt/3sAekSM
https://ift.tt/3sElmpK
Submitted August 21, 2021 at 11:41AM by 0xdea
via reddit https://ift.tt/3sAekSM
Blogspot
Understanding Network Access in Windows AppContainers
Posted by James Forshaw, Project Zero Recently I've been delving into the inner workings of the Windows Firewall. This is interesting to ...
Breaking electron-store's encryption
https://ift.tt/2WiTJ9G
Submitted August 22, 2021 at 07:52AM by veggiedefender
via reddit https://ift.tt/2WcArmi
https://ift.tt/2WiTJ9G
Submitted August 22, 2021 at 07:52AM by veggiedefender
via reddit https://ift.tt/2WcArmi
blog.jse.li
Breaking electron-store's encryption | Jesse Li
Well-known vulnerabilities in `aes-256-cbc` allow attackers to modify encrypted config files without knowing the secret key.
CVE-2021-32682 / CVE-2021-23394 - Write-up of several pre-auth RCEs in elFinder < 2.1.59
https://ift.tt/3iVdfSk
Submitted August 22, 2021 at 11:03PM by monoimpact
via reddit https://ift.tt/3y5wHjz
https://ift.tt/3iVdfSk
Submitted August 22, 2021 at 11:03PM by monoimpact
via reddit https://ift.tt/3y5wHjz
Sonarsource
elFinder - A Case Study of Web File Manager Vulnerabilities
Our case study of elFinder 2.1.57 describes several critical code vulnerabilities commonly found in web file managers and how to patch them.
macOS 11's hidden security improvements
https://ift.tt/3iUbcOr
Submitted August 23, 2021 at 01:52AM by 0xdea
via reddit https://ift.tt/386tnKo
https://ift.tt/3iUbcOr
Submitted August 23, 2021 at 01:52AM by 0xdea
via reddit https://ift.tt/386tnKo
Malwarebytes
macOS 11’s hidden security improvements
A deep dive into macOS 11's internals reveals some security surprises that deserve to be more widely known.
https://ift.tt/2Wk2YXf
https://ift.tt/2Wk2YXf
Submitted August 23, 2021 at 03:14AM by russell1492
via reddit https://ift.tt/3mpfwHq
https://ift.tt/2Wk2YXf
Submitted August 23, 2021 at 03:14AM by russell1492
via reddit https://ift.tt/3mpfwHq
Google
Real-time meetings by Google. Using your browser, share your video, desktop, and presentations with teammates and customers.
Anti-Debug JS/WASM Polyglots by Hand
https://ift.tt/3y8WhEg
Submitted August 23, 2021 at 03:54AM by netsecfriends
via reddit https://ift.tt/3B3DiNn
https://ift.tt/3y8WhEg
Submitted August 23, 2021 at 03:54AM by netsecfriends
via reddit https://ift.tt/3B3DiNn
remyhax.xyz
Anti-Debug JS/WASM by Hand
Last week a friend of mine asked me to debug/RE some phishing emails that had been sent to them. These phishing emails were visually very clever and looked identical to the real site! But as I looked at the javanoscript I frankly became embarassed for the developer.
Zoom RCE from Pwn2Own 2021 writeup
https://ift.tt/3j7VVcQ
Submitted August 23, 2021 at 05:50PM by xnyhps
via reddit https://ift.tt/2XQumwA
https://ift.tt/3j7VVcQ
Submitted August 23, 2021 at 05:50PM by xnyhps
via reddit https://ift.tt/2XQumwA
sector7.computest.nl
Zoom RCE from Pwn2Own 2021
On April 7 2021, Thijs Alkemade and Daan Keuper demonstrated a zero-click remote code execution exploit in the Zoom video client during Pwn2Own 2021. Now that related bugs have been fixed for all users (see ZDI-21-971 and ZSB-22003) we can safely detail the…
GitHub - aktsk/ipa-medit: Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.
https://ift.tt/3nfJn3q
Submitted August 23, 2021 at 06:32PM by tkmru
via reddit https://ift.tt/382H39s
https://ift.tt/3nfJn3q
Submitted August 23, 2021 at 06:32PM by tkmru
via reddit https://ift.tt/382H39s
GitHub
GitHub - aktsk/ipa-medit: Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac…
Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking. - GitHub - aktsk/ipa-medit: Memory modification tool for re-signed ipa sup...
PyHook: New little tool. A python implementation of my SharpHook project
https://ift.tt/3gpnehg
Submitted August 23, 2021 at 08:23PM by Fun_Preference1113
via reddit https://ift.tt/3ygWHsA
https://ift.tt/3gpnehg
Submitted August 23, 2021 at 08:23PM by Fun_Preference1113
via reddit https://ift.tt/3ygWHsA
GitHub
GitHub - IlanKalendarov/PyHook: PyHook is an offensive API hooking tool written in python designed to catch various credentials…
PyHook is an offensive API hooking tool written in python designed to catch various credentials within the API call. - IlanKalendarov/PyHook
Killing Defender through NT symbolic links redirection
https://ift.tt/3gqyWbj
Submitted August 24, 2021 at 02:23AM by Void_Sec
via reddit https://ift.tt/3ze8JnB
https://ift.tt/3gqyWbj
Submitted August 24, 2021 at 02:23AM by Void_Sec
via reddit https://ift.tt/3ze8JnB
Use smb2 protocol to detect remote computer os version, support win7/server2008-win10/server2019
https://ift.tt/3y9p8s9
Submitted August 24, 2021 at 09:43AM by w1n11
via reddit https://ift.tt/3kjyQDp
https://ift.tt/3y9p8s9
Submitted August 24, 2021 at 09:43AM by w1n11
via reddit https://ift.tt/3kjyQDp
GitHub
GitHub - w1u0u1/smb2os: Use smb2 protocol to detect remote computer os version, support win7/server2008-win10/server2019
Use smb2 protocol to detect remote computer os version, support win7/server2008-win10/server2019 - w1u0u1/smb2os
SSD Secure Disclosure Advisory: Find out how a vulnerability discovered in Samsung S10+/S9 kernel allows leaking of sensitive function address information.
https://ift.tt/389vgGg
Submitted August 24, 2021 at 03:44PM by SSDisclosure
via reddit https://ift.tt/2WbXaiJ
https://ift.tt/389vgGg
Submitted August 24, 2021 at 03:44PM by SSDisclosure
via reddit https://ift.tt/2WbXaiJ
SSD Secure Disclosure
SSD Advisory – Samsung S10+/S9 kernel 4.14 (Android 10) Kernel Function Address (.text) and Heap Address Information Leak - SSD…
TL;DR Find out how a vulnerability discovered in Samsung S10+/S9 kernel allows leaking of sensitive function address information. Vulnerability Summary Samsung S10+/S9 kernel […]
Cloud Security Orienteering: How to rapidly understand and secure a cloud environment
https://ift.tt/2WlJstx
Submitted August 24, 2021 at 08:40PM by ramimac
via reddit https://ift.tt/3DePRXV
https://ift.tt/2WlJstx
Submitted August 24, 2021 at 08:40PM by ramimac
via reddit https://ift.tt/3DePRXV
tl;dr sec
Cloud Security Orienteering
How to orienteer in a cloud environment, dig in to identify the risks that matter, and put together actionable plans that address short, medium, and long term goals.
Cobalt Strike Aggressor Script - Profiles Systems AV/EDR via Windows Registry
https://ift.tt/3gtvKM8
Submitted August 24, 2021 at 08:55PM by eth3real
via reddit https://ift.tt/3y9dgX3
https://ift.tt/3gtvKM8
Submitted August 24, 2021 at 08:55PM by eth3real
via reddit https://ift.tt/3y9dgX3
GitHub
GitHub - optiv/Registry-Recon: Cobalt Strike Aggressor Script that Performs System/AV/EDR Recon
Cobalt Strike Aggressor Script that Performs System/AV/EDR Recon - optiv/Registry-Recon
Tutorial: 32-bit Stack-based Buffer Overflow
https://ift.tt/3DecAn9
Submitted August 25, 2021 at 02:36AM by Kondencuotaspienas
via reddit https://ift.tt/3sLYGUh
https://ift.tt/3DecAn9
Submitted August 25, 2021 at 02:36AM by Kondencuotaspienas
via reddit https://ift.tt/3sLYGUh
www.ired.team
32-bit Stack-based Buffer Overflow
URL filter subversion - new web app vuln
https://ift.tt/3sLWs7p
Submitted August 25, 2021 at 06:00PM by jodsonleandross
via reddit https://ift.tt/3yiuHV8
https://ift.tt/3sLWs7p
Submitted August 25, 2021 at 06:00PM by jodsonleandross
via reddit https://ift.tt/3yiuHV8
sidechannel.blog
URL Filter Subversion | SideChannel – Tempest
How failures related to validating conditions based on URLs can lead to security issues